Cisco Umbrella Design Guide
Total Page:16
File Type:pdf, Size:1020Kb
Design Guide Cisco Public Cisco Umbrella Design Guide June, 2021 © 2021 Cisco and/or its affiliates. All rights reserved. Page 1 of 120 Contents Overview .......................................................................................................................................... 3 Solution Overview ............................................................................................................................. 4 Packet flow through Umbrella SIG..................................................................................................................... 4 DNS-Layer Security ............................................................................................................................................ 5 Secure Web Gateway (SWG).............................................................................................................................. 6 Cloud-Delivered Firewall (CDFW) ...................................................................................................................... 7 Cloud access security broker (CASB) ............................................................................................................... 8 Threat Intelligence .............................................................................................................................................. 8 Architecture Overview ...................................................................................................................... 9 Umbrella Business Flows .................................................................................................................................. 12 Attack Surfaces ................................................................................................................................................ 12 Umbrella Integrations ...................................................................................................................... 13 Cisco SD-WAN integration ............................................................................................................................... 14 Cisco SecureX Integration ............................................................................................................................... 15 Cisco Advanced Malware Protection (AMP) and Threat Grid ........................................................................ 15 Cisco DUO Integration ...................................................................................................................................... 17 Design Introduction......................................................................................................................... 17 Headquarters (HQ) ............................................................................................................................................ 17 Branch ................................................................................................................................................................ 18 Roaming ............................................................................................................................................................. 20 SIG Deployment ............................................................................................................................. 21 Headquarters (HQ) ............................................................................................................................................ 22 Branch ................................................................................................................................................................ 53 Roaming Computers ......................................................................................................................................... 75 Appendix ........................................................................................................................................ 97 Appendix A: Duo Access Gateway for SAML Configuration .......................................................................... 97 Appendix B: Viptela Configuration Template Summary ............................................................................... 103 Feature Templates 106 Device Templates 110 CLI Configuration 111 Appendix C: Configuring Tenant Controls .................................................................................................... 113 Appendix D: Configuring File Policies ........................................................................................................... 117 © 2021 Cisco and/or its affiliates. All rights reserved. Page 2 of 120 Overview Security is shifting and converging in the cloud. You may hear different names for this trend such as secure internet gateway (SIG), edge security, Secure Access Service Edge (SASE), and more. It can get confusing. Regardless of what you call it, it denotes: multiple security functions integrated in one cloud service; flexibility to deploy security services how and where you choose; ability to secure direct-to-internet access, cloud app usage and roaming users; plus, no appliances to deploy. Cisco Umbrella is a cloud-delivered security service that brings together essential functions that you can adopt incrementally, at your pace. Umbrella unifies secure web gateway, DNS security, cloud-delivered firewall, cloud access security broker functionality, and threat intelligence. Deep inspection and control ensures compliance with acceptable-use web policies and protects against internet threats. Accelerated threat detection/response and centralized management makes it ideal for decentralized networks. Cisco Umbrella SIG Overview © 2021 Cisco and/or its affiliates. All rights reserved. Page 3 of 120 Solution Overview Umbrella offers a broad set of security functions that until now required separate firewall, web gateway, threat intelligence, and cloud access security broker (CASB) solutions. By enabling all of this from a single, cloud- delivered service and dashboard, Umbrella significantly reduces the time, money, and resources previously required for deployment, configuration, and integration tasks. It can be integrated with your SD-WAN implementation to provide a unique combination of performance, security, and flexibility that delights both your end users and security team. Packet flow through Umbrella SIG Policy flow-enforcement that works together The following components are integrated seamlessly in a single, cloud-delivered service: ● Umbrella DNS is resolved first. It is the first check for malicious or unwanted domains and is based on the defined DNS policies. This reduces the quantity of traffic that is sent to the CDFW and SWG, improving responsiveness and performance ● All traffic that has made it through DNS checks will be inspected by the CDFW. The firewall provides visibility and control for outbound internet traffic across all ports and protocols (L3/L4) as well as L7 ● The SWG will inspect any traffic that is destined for 80/443 after it has been permitted by the CDFW to provide a deeper security inspection. It will also apply application, visibility and control policies © 2021 Cisco and/or its affiliates. All rights reserved. Page 4 of 120 DNS-Layer Security Umbrella DNS Security Capabilities This is the first line of defense against threats because DNS resolution is the first step in internet access. Enforcing security at the DNS and IP layers, Umbrella blocks requests to malicious and unwanted destinations before a connection is even established - stopping threats over any port or protocol before they reach your network or endpoints. As a cloud-delivered service, it: ● Provides the visibility needed to protect internet access across all network devices, office locations, and roaming users ● Logs and categorizes DNS activity by type of security threat or web content and the action taken — whether it was blocked or allowed ● Retains logs of all activity for 30 days (export for longer retention), ready to recall for deeper investigation ● Can be implemented quickly to cover thousands of locations and users in minutes, to provide immediate return on investment This level of protection is enough for some locations and users, yet others need additional visibility and control to meet compliance regulations and further reduce risk. © 2021 Cisco and/or its affiliates. All rights reserved. Page 5 of 120 Secure Web Gateway (SWG) Umbrella Secure Web Gateway Capabilities Umbrella includes a full cloud-based secure web gateway (proxy) that can log and inspect all of your web traffic for greater transparency, control, and protection. The SWG functionality includes: ● The ability to efficiently scan all downloaded files for malware and other threats using the Cisco Advanced Malware Protection (AMP) SHA hash lookups and additional anti-virus engines ● Full or selective SSL decryption to further protect your organization from hidden attacks and time- consuming infections ● Granular app controls to block specific user activities in select apps (e.g. file uploads to Dropbox, attachments to GMail, post/shares on Facebook) ● File type blocking (e.g. block download of .exe files) ● Detailed reporting with full URL addresses, network identity, allow or block actions, plus the external IP address ● Content filtering by category or specific URLs to block destinations that violate policies or compliance regulations ● Sandboxing of files using an integrated cloud delivered Threat Grid. When a